================
@@ -3300,6 +3300,73 @@ remove the const qualifier from the original declaration
or use a mutable copy.
### alpha.cplusplus
+(alpha-cplusplus-danglingptrderef)=
+
+#### alpha.cplusplus.DanglingPtrDeref (C++)
+
+Check for dereferences of pointers that refer to an object whose
+lifetime has already ended. Such a pointer is dangling. The checker
+reports it when it is dereferenced and when it is passed to a function.
+This includes a dereference in a return statement. A return statement that
+does not dereference the pointer does not lead to a report. Such a case is
+reported by the {ref}`core-StackAddressEscape` checker.
+
+Each object is reported at most once on an execution path. If the same dangling
+pointer is used several times then only the first use is reported.
+
+```cpp
+void test_deref() {
+ int *ptr = 0;
+ {
+ int num = 5;
+ ptr = #
+ } // note: 'num' is destroyed here
+ *ptr = 6; // warn: use of 'num' after its lifetime ended
+}
+
+int test_deref_in_return() {
+ int *ptr = 0;
+ {
+ int num = 5;
+ ptr = #
+ } // note: 'num' is destroyed here
+ return *ptr; // warn: use of 'num' after its lifetime ended
+}
+
+void test_in_scope() {
+ int num = 5;
+ int *ptr = #
+ {
+ *ptr = 6; // no warning, 'num' is still in scope
+ }
+}
+```
+
+The `-analyzer-config cfg-lifetime=true` option is a prerequisite for these
----------------
steakhal wrote:
I think a nice followup could be for you to push for enabling cfg-lifetimes by
default for the analyzer.
https://github.com/llvm/llvm-project/pull/216688
_______________________________________________
cfe-commits mailing list
[email protected]
https://lists.llvm.org/cgi-bin/mailman/listinfo/cfe-commits